Privacy Policy

Last updated: 2 August 2026

This Privacy Policy explains how personal data is processed when users visit hoteltramonto.it, submit an enquiry or availability request, subscribe to promotional communications, or interact with Hotel Residence Tramonto’s online services.

1. Data Controller

Hotel Tramonto S.r.l., operating under the name Hotel Residence Tramonto

Registered office: Via Trieste, 85 – 71012 Rodi Garganico (FG), Italy

VAT number and Tax Code: 04150580712

Email: info@hoteltramonto.it

Telephone: +39 0884 965368

2. Personal data processed

Depending on the service used, the following categories of personal data may be processed:

Please do not enter health data or other particularly sensitive information in general contact forms. Where such information is genuinely necessary to organise a stay, users should contact the hotel directly. Special categories of personal data will only be processed where an appropriate legal basis exists, including explicit consent or a legal obligation.

3. Purposes, legal basis and retention

Purpose Legal basis Indicative retention period
Responding to requests for information, availability, quotations or contact. Taking steps at the request of the data subject prior to entering into a contract, Article 6(1)(b) GDPR. Generally up to 24 months after the request has been closed, unless a booking follows or retention is needed to protect legal rights.
Managing bookings, stays, assistance, payments and requested services. Performance of a contract, Article 6(1)(b) GDPR. For the duration of the relationship and afterwards for the periods required by law and to protect legal rights.
Complying with tax, accounting, administrative, public-security and other legal obligations. Compliance with a legal obligation, Article 6(1)(c) GDPR. Normally 10 years for accounting and administrative documentation, unless a different period is required by law.
Sending newsletters, offers and promotional communications. Consent, Article 6(1)(a) GDPR. Until consent is withdrawn and, as a rule, no longer than 24 months from the last relevant interaction unless renewed.
Ensuring website security, preventing misuse, fraud and unauthorised access, managing faults and defending legal rights. The Controller’s legitimate interests, Article 6(1)(f) GDPR. Technical logs are generally retained for up to 30 days, unless required for security incidents, disputes or legal obligations.
Measuring website use, creating statistics, personalising content and measuring advertising campaigns through non-essential technologies. Consent, Article 6(1)(a) GDPR and the applicable rules on cookies and similar technologies. According to the duration stated in the cookie preference panel and the policies of the relevant providers.

These periods may be extended where necessary to establish, exercise or defend legal claims, manage a dispute or comply with an authority’s request.

4. Provision of personal data

Data marked as required in enquiry or contact forms is necessary to receive a response and, where applicable, to provide the requested service. Failure to provide it may prevent the Controller from processing the request.

Consent for promotional purposes and for non-essential cookies or tracking technologies is optional, separate and may be withdrawn at any time without affecting the possibility of requesting information or booking a stay.

5. Processing methods and security

Personal data is processed using paper and electronic means by authorised staff and appointed suppliers, with technical and organisational measures appropriate to the level of risk. The Controller applies data-minimisation, access-control, account-protection, backup and system-monitoring measures.

No system can guarantee absolute security. In the event of a personal data breach, the Controller will follow the procedures required by law, including any necessary notifications to the supervisory authority and affected individuals.

6. Recipients and processors

Personal data may be disclosed, where necessary, to:

Providers processing data on behalf of the Controller are appointed as processors under Article 28 GDPR where required. Other parties may act as independent controllers under their own privacy policies.

7. Third-party services and transfers outside the European Economic Area

The website may integrate services supplied by providers including Google and Meta, such as analytics and advertising tools, maps, videos, anti-spam systems, social plugins or links to messaging services. Non-essential services must be activated in accordance with the choices expressed through the consent-management system.

Some providers may process personal data in countries outside the European Economic Area. Where this occurs, transfers take place, according to the provider’s statements and the service concerned, on the basis of an adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses or another safeguard permitted by Articles 44 and following of the GDPR.

8. Cookies and similar technologies

The website uses technical cookies required for operation and may, with consent, use cookies or similar technologies for analytics, campaign measurement, personalisation and advertising. Preferences may be changed or withdrawn at any time through the “Manage cookie preferences” function available on the website.

For information on categories, purposes, providers and duration, please see the Cookie Policy.

9. Newsletters and promotional communications

Promotional communications are sent only where valid consent has been obtained, except in any specific cases permitted by law. Consent may be withdrawn through the unsubscribe link included in emails, where available, or by writing to info@hoteltramonto.it.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

10. Children’s data

The website is not aimed directly at children for the independent conclusion of bookings or subscription to marketing communications. Data relating to children that is necessary to organise a stay must be provided by a parent, legal guardian or another person authorised to do so.

11. Automated decision-making

The Controller does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals. Any statistical or advertising segmentation depends on consent and on the features of the third-party services used.

12. Data subject rights

Where provided for by the GDPR, data subjects may request:

Requests may be sent to info@hoteltramonto.it. The Controller may request information necessary to verify the requester’s identity.

13. Right to lodge a complaint

Data subjects have the right to lodge a complaint with the Italian Data Protection Authority , or with the competent supervisory authority in the Member State where they live or work, or where the alleged infringement occurred.

14. External links

The website may contain links to websites, social networks, review platforms or external services. Once the user leaves this website, data processing is governed by the third party’s own privacy policy. The Controller does not control processing independently carried out by those parties.

15. Updates to this Privacy Policy

This Privacy Policy may be amended to reflect changes in law, organisation or technology. The updated version will be published on this page together with the date of the latest update. Where changes are material, an additional notice may be displayed on the website.